CVE-2024-22447 PUBLISHED

Assigner: dell
Reserved: 10.01.2024 Published: 16.06.2026 Updated: 16.06.2026

Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious dll., leading to arbitrary code execution.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 6.7

Product Status

Vendor Dell
Product Peripheral Manager
Versions Default: unaffected
  • affected from 0 to 1.7.3 or later (excl.)

Credits

  • Dell Technologies would like to thank Yue Liu From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue. finder

References

Problem Types

  • CWE-427: Uncontrolled Search Path Element CWE